Описание
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to access confidential issue details due to incorrect authorization checks.
Ссылки
- Release Notes
- Issue Tracking
- Permissions Required
Уязвимые конфигурации
Конфигурация 1Версия от 12.0.0 (включая) до 18.10.8 (исключая)Версия от 12.0.0 (включая) до 18.10.8 (исключая)Версия от 18.11.0 (включая) до 18.11.5 (исключая)Версия от 18.11.0 (включая) до 18.11.5 (исключая)Версия от 19.0.0 (включая) до 19.0.2 (исключая)Версия от 19.0.0 (включая) до 19.0.2 (исключая)
Одно из
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 15%
0.00236
Низкий
3.1 Low
CVSS3
Дефекты
CWE-863
Связанные уязвимости
CVSS3: 3.1
github
около 2 месяцев назад
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authenticated user to access confidential issue details due to incorrect authorization checks.
EPSS
Процентиль: 15%
0.00236
Низкий
3.1 Low
CVSS3
Дефекты
CWE-863